Feature transformation and Mutual Information for DNS tunneling analysis
Contributo in Atti di convegno
Data di Pubblicazione:
2016
Abstract:
Tunneling attacks are executed to bypass security policies or leak sensitive data outside of a network. In this paper, we propose an innovative algorithm to profile DNS tunnels. Our approach combines Principal Component Analysis and Mutual Information. The proposed algorithm is validated on a live network. Results show that, under specific conditions, anomalies are correctly characterized through the proposed method. Other cases require instead further investigation.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
-
Elenco autori:
Cambiaso, Enrico; Aiello, Maurizio; Mongelli, Maurizio; Papaleo, Gianluca
Link alla scheda completa: